Hacker News

Top stories

Live mirror
30 storiesupdated just nowView source snapshot
  1. Astra for Law(openai.com ↗)
    361comments
  2. Bonsai 2 27B: Near-Lossless Compression in a 9x Smaller Footprint(prismml.com ↗)
    75comments
  3. Goose: 1.16x faster than C++ and 1.12x than safe Rust, while memory safe(github.com/aardappel ↗)
    24comments
  4. Bend – A language that blocks AI mistakes via proof, on CPU and GPU(bend-lang.com ↗)
    153comments
  5. Hister: A private search engine for the pages you visit and the files you keep(github.com/asciimoo ↗)
    137comments
  6. Wax motor(wikipedia.org ↗)
    50comments
  7. Fujitsu launches made-in-Japan next-generation CPU FUJITSU-MONAKA(global.fujitsu ↗)
    198comments
  8. Alibaba releases Qwen 3.8 Omni Flash(qwen.ai ↗)
    5comments
  9. Telstra outage: The night a network decided the year was 2006(netnod.se ↗)
    2comments
  10. Flet 1.0 – Build cross-platform apps in Python(flet.dev ↗)
    34comments
  11. Diplodocus, Long Thought Exclusively American, Turns Up in Spain(sci.news ↗)
    20comments
  12. More than 100k people in Japan are now aged 100 or older(bbc.com ↗)
    122comments
  13. I Put Nam A2-Lite Inside an iRig HD X(playtaurus.com ↗)
    1comments
  14. CrowdSec Source Code Leak(crowdsec.net ↗)
    40comments
  15. Infinite-Parameter LLMs: Generating and Adapting Weights from Live Data(arxiv.org ↗)
    34comments
  16. How Uber Protects Against Retry Storms(uber.com ↗)
    23comments
  17. Why I didn’t sign the Fields medallists’ letter(gowers.wordpress.com ↗)
    313comments
  18. The most important product decision is what you don't build(liamnugent.me ↗)
    19comments
  19. Rate limits on GitLab.com are changing(about.gitlab.com ↗)
    106comments
  20. How do we prevent mathemathics from devolving into the Medieval Era of secrecy?(mathoverflow.net ↗)
    56comments
  21. CCC invites all model citizens to 40C3(ccc.de ↗)
    180comments
  22. TSMC revealing details about next gen A14 node(mapyourshow.com ↗)
    36comments
  23. The American Religion of Self-Storage Facilities(newyorker.com ↗)
    343comments
  24. Landing the Space Shuttle – A Flying Machine and the Thrill of a Lifetime(eaa.org ↗)
    5comments
  25. Zettascale (YC S24) Is Hiring ASIC/FPGA Engineers to Build Chips for ASI(zscc.ai ↗)
    discuss
  26. Show HN: Snapdrop: Instantly share files between devices. No setup, no signup(snapdrop.me ↗)
    19comments
  27. Running Ubuntu on the Lenovo IdeaPad Duet(vhaudiquet.fr ↗)
    25comments
  28. Computer Reset, Dallas(dfarq.homeip.net ↗)
    2comments
  29. Launch HN: Skillsync (YC W26) – AI chat sessions made portable across agents
    50comments
  30. Show HN: Share your AI Setup, Learn from others(mysetup.ai ↗)
    103comments

Memory Sealing "Mseal" System Call Merged for Linux 6.10

6 pointsby 2y agophoronix.com
3 comments
2y agoHN ↗

The mseal patch: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/lin...

Userspace API > System Calls: https://www.kernel.org/doc/html/next/userspace-api/index.htm...

kernel.org/doc/html/next/userspace-api/mseal.html: https://www.kernel.org/doc/html/next/userspace-api/mseal.htm... :

Modern CPUs support memory permissions such as RW and NX bits. The memory permission feature improves security stance on memory corruption bugs, i.e. the attacker can’t just write to arbitrary memory and point the code to it, the memory has to be marked with X bit, or else an exception will happen.

Memory sealing additionally protects the mapping itself against modifications. This is useful to mitigate memory corruption issues where a corrupted pointer is passed to a memory management system. For example, such an attacker primitive can break control-flow integrity guarantees since read-only memory that is supposed to be trusted can become writable or .text pages can get remapped. Memory sealing can automatically be applied by the runtime loader to seal .text and .rodata pages and applications can additionally seal security critical data at runtime.

A similar feature already exists in the XNU kernel with the VM_FLAGS_PERMANENT flag [1] and on OpenBSD with the mimmutable syscall [2].

NX bit, Memory tagging, Modified Harvard architecture: https://news.ycombinator.com/item?id=36726077#36740262

TEE, SGX, .data, .code: https://news.ycombinator.com/item?id=33584502

2y agoHN ↗

Thanks! Another important bit:

sealing changes the lifetime of a mapping, i.e. the sealed mapping won’t be unmapped till the process terminates or the exec system call is invoked. Applications can apply sealing to any virtual memory region from userspace, but it is crucial to thoroughly analyze the mapping’s lifetime prior to apply the sealing.

2y agoHN ↗

Why is the sealed mapping unmapped on exec*()? What about spawn and fork?

Are there libraries for handling this yet?

IIRC, with CPython the NX bit doesn't work when any imported C extension has nested functions / trampolines

How should CPython support the mseal() syscall?